Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: HTTP Header Usage Statistics - Internet Security | DShield HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
Content-Length
X-Frame-Options
Strict-Transport-Security
Last-Modified
Accept-Ranges
Pragma
X-Content-Type-Options
X-Powered-By
CF-RAY
ETag
Link
Expect-CT
Via
X-XSS-Protection
X-Cache
Age
Access-Control-Allow-Origin
Content-Security-Policy
Content-Language
P3P
X-UA-Compatible
X-Cache-Hits
X-Served-By
X-Amz-Cf-Id
X-Varnish
Referrer-Policy
X-Xss-Protection
X-Timer
CF-Cache-Status
X-FRAME-OPTIONS
Access-Control-Allow-Headers
X-AspNet-Version
X-Request-Id
Access-Control-Allow-Methods
X-Runtime
X-Download-Options
Access-Control-Allow-Credentials
X-Drupal-Cache
X-Cacheable
X-Request-ID
Alt-Svc
X-Generator
Content-Security-Policy-Report-Only
X-Check
X-AspNetMvc-Version
X-Adblock-Key
Status
X-Cache-Status
Timing-Allow-Origin
X-DNS-Prefetch-Control
X-Permitted-Cross-Domain-Policies
X-Template
X-Language
X-Iinfo
Content-Encoding
X-Content-Security-Policy
X-Turbo-Charged-By
X-CDN
X-Buckets
X-Type
Keep-Alive
Xkey
X-AH-Environment
X-Cache-Group
WPE-Backend
X-Pass-Why
Access-Control-Max-Age
X-Backend
X-Age
CF-Ray
X-POWERED-BY
Upgrade
X-Server
Access-Control-Expose-Headers
EagleId
X-Via
X-Nginx-Cache-Status
X-Server-Powered-By
X-Drupal-Dynamic-Cache
X-Pingback
X-Varnish-Cache
X-Amz-Id-2
X-Amz-Request-Id
X-Hacker
Grace
X-UA-Device
X-Swift-SaveTime
X-Swift-CacheTime
X-Robots-Tag
Ali-Swift-Global-Savetime
P3p
Cf-Railgun
X-LiteSpeed-Cache
X-Proxy-Cache
X-Envoy-Upstream-Service-Time
X-Page-Speed
X-Ua-Compatible
Request-Context
Content-Location
X-Device
X-Ac
X-Styx-Req-Id
X-Pantheon-Styx-Hostname
X-Cnection
X-Amz-Version-Id
X-Host
X-Node
X-Cache-Lookup
Surrogate-Control
X-Server-Id
X-Backend-Server
X-Rq
X-Rack-Cache
X-Response-Time
X-WebKit-CSP
X-Application-Context
X-Readtime
EagleEye-TraceId
X-OneAgent-JS-Injection
Server-Timing
X-Cloud-Trace-Context
X-Url
Pinterest-Generated-By
X-CST
Report-To
Request-Id
X-Instart-Request-ID
X-TTL
X-Country
X-Px
X-ORACLE-DMS-ECID
X-Clacks-Overhead
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Feature-Policy
Edge-Control
X-Country-Code
Rating
Allow
X-Dns-Prefetch-Control
X-ESI
X-Powered-CMS
X-TtlSet
X-Vname
X-PC
NEL
X-FTR-Request-ID
Charset
X-DataDome
X-Origin-Cache
X-Server-Name
X-DynaTrace-JS-Agent
X-DynaTrace
X-MS-InvokeApp
X-Cached
X-Vhost
X-Goog-Hash
X-GitHub-Request-Id
X-Recruiting
X-VARITI-CCR
X-Varnish-TTL
RTSS
X-Version
X-F-Cache
Content-MD5
X-Exp-Variant
X-Exp-Id
X-Kinja-Server
X-Kinja
X-Cdn-Fetch
X-Kinja-Revision
X-Geo-Segment
X-Kinja-Build
X-Powered-By-Plesk
X-GoogleNews-Bot
Accept-CH
Public-Key-Pins
X-D2id
PB-RID
PB-PID
X-Mobile-Rewrite
Arc-Version
X-Mod-Pagespeed
MS-Author-Via
Verso
X-Client-IP
Pinterest-Version
X-Upstream-Env
X-Pinterest-Rid
X-Abt-Application-Version
X-Dispatcher
SPRequestGuid
X-SRCache-Fetch-Status
X-SRCache-Store-Status
X-SharePointHealthScore
X-N
X-ORACLE-DMS-RID
X-Amz-Rid
X-Ruxit-JS-Agent
Nginx-Cache
X-CF-Powered-By
Accept-CH-Lifetime
X-Navigation-Version
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
X-Dw-Request-Base-Id
X-Trace
X-Fastly-Request-ID
Paypal-Debug-Id
X-Forwarded-Proto
X-DIS-Request-ID
X-Origin-Upstream-Status
X-T
DynaTrace
X-Server-ID
X-Hits
X-Upstream
X-Grace
X-Varnish-Age
SPIisLatency
SPRequestDuration
Arr-Disable-Session-Affinity
X-Amz-Meta-S3cmd-Attrs
TCN
AR-PoweredBy
X-Id
AR-ATIME
X-Oracle-Dms-Rid
X-Pad
X-Shield-Request-Id
AR-CACHE
X-Content-Options
X-Content-Digest
X-NF-Request-ID
Access-Control-Request-Method
X-HW
Realpath
X-Mrf-Item-Lastmod
X-Mrf-Section-Lastmod
MRF-Tech
Mrf-Cache-Status
X-Kinsta-Cache
X-IPLB-Instance
X-Acc-Meta-Resource-Type
X-Cache-Hit
X-Goog-Metageneration
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Stored-Content-Length
X-Goog-Generation
X-Logged-In
X-B
X-Vcap-Request-Id
X-FastCGI-Cache
X-Debug
X-SS-Set-Cookie
X-Wix-Server-Artifact-Id
X-XRDS-Location
X-Ser
Service-Worker-Allowed
S
Tracecode
X-MSEdge-Ref
X-Cache-Key
Server-Name
X-FTR-Cache-Status
X-FTR-Realm
X-PressLabs-Stats
X-FTR-DC
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
X-Frontend
X-FTR-Backend
X-NewRelic-App-Data
AMP-Access-Control-Allow-Source-Origin
Fastly-Restarts
X-FTR-Expires
Rt-Fastcgi-Cache
X-Accel-Buffering
AR-SID
Surrogate-Key
X-Forwarded-For
Fastcgi-Cache
Alternate-Protocol
Backend-Timing
Eomportal-Instance
X-Analytics
X-Cache-Rule
X-HS-Hub-Id
X-HS-Content-Id
Host
TP-Cache
TP-L2-Cache
X-Revision
X-Rid
X-Srv
Cleartype
FilterID
Cache-Status
Public-Key-Pins-Report-Only
X-Ttl
X-FTR-Cache-Host
X-Debug-Info
X-Whom
X-User-Agent
Front-End-Https
X-Do-Not-Hack
X-Akam-SW-Version
Permitted-Cross-Domain-Policies
X-HeyJason
ServerID
X-AOL-HN
X-XRDS-LOCATION
X-Varnish-Backend
X-Mobile
Accept-Charset
X-GUploader-UploadID
X-Webkit-CSP
X-Cdn
X-RateLimit-Remaining
X-TA-CDN-Provider
X-Cache-2
X-Iejgwucgyu
X-Kinja-Server-Push
X-Via-JSL
X-Request-Processing-Time
X-Request-Received
X-VCache
X-NWS-LOG-UUID
X-Zen-Fury
X-Content-Powered-By
X-Oneagent-Js-Injection
X-Cached-By
X-WPE-Loopback-Upstream-Addr
X-App-Environment
X-LB-Cache
X-Magnolia-Registration
X-Tumblr-Pixel-0
Viewport
X-Tumblr-Pixel
X-Cluster
X-Cache-Control
X-Tumblr-User
X-Page-Id
X-Varnish-Hostname
X-Request-Guid
X-Handled-By
Host-Header
X-Akamai-Edgescape
X-Node-Name
X-TT
X-BCube-Filmed-By
X-Device-Type
X-Correlation-Id
X-B-Cache
X-FB-Debug
X-Platform-Server
X-Content-Security-Policy-Report-Only
X-Signature
X-B3-Sampled
X-Framework
Upgrade-Insecure-Requests
DC
Liferay-Portal
Cache-Tag
X-Instance
X-Middleton-Display
X-Sol
Display
X-Amzn-Trace-Id
X-Cache-Server
X-Hostname
MicrosoftSharePointTeamServices
X-Origin-Server
Server-Node
X-Webkit-Csp
X-B3-Traceid
X-TT-TIMESTAMP
X-Fastcgi-Cache
X-Accel-Expires
X-WA-Info
X-Varnish-Server
Source
Retry-After
X-Distil-CS
X-Servedby
X-Contextid
HitInfo
HitType
Server-Info
X-Seen-By
X-Wix-Request-Id
X-Cache-Action
X-Cache-Operation
X-Edge-Location
Content-Style-Type
Content-Script-Type
X-Amz-Replication-Status
User-Agent
Webserver
X-GeoIP
SRV
X-RequestSource
X-Tumblr-Pixel-2
X-Tumblr-Pixel-1
X-WebKit-CSP-Report-Only
X-Jobs
Actual-Object-TTL
X-S
X-APP-VERSION
X-Status
GEO-INFO
AsisCache
X-FW-Static
X-FW-Serve
X-Edge-Cache
X-Edge-Cache-Key
X-FW-Hash
X-FW-Type
X-Generated-By
X-FW-Server
X-Region
X-Response-Served-From
X-Adobe-Content
X-Adobe-Loc
X-Newrelic-App-Data
X-UUID
X-Drupal-Cache-Tags
X-TX-ID
ServedBy
X-Locale
X-Cache-NE
X-Varnish-Hits
X-Yottaa-Metrics
X-Yottaa-Optimizations
Refresh
Response
Healthy
X-Port
X-Middleton-Response
X-Geo-Country
X-Hyper-Cache
X-DataStream-Cache-Status
X-Esi
X-ATG-Version
Payment
X-Cache-TTL-Remaining
S-Cnection
IBM-Web2-Location
X-Content-Type
X-Amz-Server-Side-Encryption
X-Varnish-Grace
Datacenter
Edge-Cache-Tag
X-Daa-Tunnel
X-Cache-Age
X-HS-Cache-Config
Filters
Country
X-AppVersion
X-Activity-Id
NGB
X-Az
X-Cache-Remote
Served-By
X-Pc-Key
X-Pc-Appver
X-Pc-Hit
HostName
X-Cache-TTL
X-Varnish-IP
Powered-By-ChinaCache
X-HS-Combine-CSS
X-Sucuri-ID
Pagespeed
X-Cacheable-TTL
X-Vg-Webcache
X-App-Server
X-UA
X-Akamai-Transformed
X-Mode
X-Kong-Proxy-Latency
X-RemovedCookies
Machine
Load-Balancing
X-Kong-Upstream-Latency
X-ProcessESI
X-Cache-Var-Map
X-Cache-Var
X-Rendered-As
X-RN-RSRV
X-Detected-As
X-Is-Bot
X-Proxied
Meta-Geo
X-Rule
X-CDN-Forward
X-FC-Vary-Parameters
X-Mrs-Cache
X-Rocket-Nginx-Bypass
X-Mrs-Cache-Hits
X-Mshield-Cache-Status
X-Mrs-Age
X-Proxy
TWC-Connection-Speed
TWC-Device-Class
X-Varnish-Cache-Hits
TWC-GeoIP-LatLong
Access-Control-Allow-Method
Cache-Name
TWC-GeoIP-Country
OT-Force-Account-Verify
DB-Nickname
Property-Id
Mn-Server-Ip
Backend
Webcakes-App-Version
X-ProxyCache-Status
X-ProxyCache-Key
TWC-Locale-Group
X-BYPASS-REASON
X-Origin-Hint
X-Origin
X-Grey
X-Hosted-By
X-Human
X-OCL
X-Tb
X-PCL
X-Cache-Category-Id
Webcakes-App-Name
User-Cache-Control
Webcakes-Region
X-Amz-Meta-Surrogate-Control
TWC-Privacy
X-ServerID
Azure-Version
X-EIG-Tracking-Id
X-JoinUs
X-Loop
Azure-RegionName
Azure-InstanceId
X-Hit
X-Generated
L5d-Success-Class
Azure-SiteName
X-Format
X-Original-Request
X-Upgrade-Enabled
X-Varnish-Cacheable
X-Debug-Cache
X-TNCMS
S-Rt
X-CDN-Cache
X-Zipkin-Id
X-Section
X-OVcl
ServerName
X-OVcl-Cache
X-BB-IP
X-Routing-Service
Now
X-Access
Azure-SlotName
X-Correlation-ID
X-HOST
X-Cache-Config
X-Www-Served-By
X-Environment-Context
X-VWS-Id
X-AWS-Id
X-Agile-Id
X-Upstream-CT
X-Upstream-HT
X-Agile
X-Agile-Age
X-Viewer-Country
X-ApacheServer
X-Via-Fastly
X-PERF
X-Timing-Wait
X-Proxy-Build
X-Pubstack
X-SplitTest
X-TWH-CORRELATION-ID
X-NodeID
X-IP
X-L-Path
X-LJ-Flow-ID
X-NGENIX-Cache
Selected-FE
X-App-Name
Cache-Key
Fastcgi-X-Cache-Version
Access-Control-Request-Headers
Fastcgi-Useragent
Fastcgi-X-Cache
X-Ocache
X-CCM
X-Source
X-Drupal-Cache-Contexts
X-URL
From-Origin
X-Site-Version
X-Origin-CC
X-Xfnlog-Site
X-Nginx-Cache
X-Amz-Apigw-Id
X-Backend-Name
X-Amzn-RequestId
X-Unique-ID
Cache
X-RateLimit-Limit
LB
X-Litespeed-Cache
X-Akamai-Request-ID
X-Forwarded-Host
Fastly-SSL
X-Storage
X-Vgn-Hpd-Reason
X-Feature
X-Pc-Host
X-Pc-Date
X-Ms-Version
ViewerVersion
X-Ms-Lease-Status
X-Ms-Request-Id
X-App-Version
X-Ms-Blob-Type
X-Varnish-Beresp-Status
X-M-Log
X-Qnm-Cache
NtCoent-Length
X-Varnish-Beresp-Grace
X-M-Reqid
X-Real-IP
X-Birta-Cache-Post
X-Birta-Served
X-Labrador-Cache-Channel
AR-Request-ID
X-VG-TLSProxy
X-NCache
X-Time-Microsecs
X-Internal-Host
X-Release
X-Distributor
X-Ruxit-Js-Agent
X-Cluster-Node
X-Microcachable
Time
Xserver
X-EdgeConnect-Cache-Status
CACHE
Ar-Sid
X-B3-Spanid
X-Powered-By-ANYU
WZWS-RAY
X-NC
X-Real-Ip
X-Request-Time
X-Guploader-Uploadid
X-SERVER-NAME
X-Sucuri-Cache
X-Cache-Enabled
Ajk
Ec-Rule-Version
Fly-Cache
Cache-Prefix
BehaviorPad-Version
NGX
Viewtype
Arc-Country
Fly-Request-Id
IsBot
Www
Meta-Geo-Continent
MD5-Digest
Mobile-Detection-Method
Server-Int
V-Age
Rendered-Blocks
T-Server
X-Cache-Bucket
X-Rewrite-Enabled
X-Request-UUID
X-Rojux
X-S-Cookie
X-Server-By
X-ScT
X-Region-Sid
X-Redis-Cache
X-Logtrace-Id
X-Irp-Debug
X-NU-AKA-ACS-Version
X-Org
X-PAYTM-SRV-ID
X-Server-Time
X-SIPLIST1
X-Via-Edge
X-Via-CDN
X-Via-SSL
X-WebServer
Xc-Version
X-VG-WebServer
X-UE-Client-Country
X-Store
X-SRCache-Key
X-Transaction
X-Trv-Group
X-Twitter-Response-Tags
X-IN-WAF
X-IN-SSL-APIGATEWAY
X-B-Cookie
X-ARC
X-BB-ID
X-CF-Lambda-Fn
X-CF-Lambda-Version
X-Application
X-Accel-Expires-Debug
X-A-Dam
X-A-Ccd
X-A-Dcw
X-A-Dgt
X-A-Wwc
X-Connection-Hash
X-CUA
X-G
X-From
X-Generated-In
X-Generation-Time
X-IN-APIGATEWAY
X-DPWN-IS-SECURE
X-Dispatcher-Server
X-Date
X-D
X-Destination
X-Developer
X-Died
X-A
VivaBuild
ProcessTime
X-Cache-Backend
Cneonction
X-Varnish-Beresp-Ttl
X-FireWall-Port
Origin-Cache-Control
Origin-Edge-Control
X-Amz-Meta-Cache-Control
X-CGP
NodeID
X-Crawler
Country-Code
X-UA-Device-Type
X-UnsetCookies
Pragrma
Powered
Frame-Options
X-CS
X-S-Maxage
X-Amz-Cf-Pop
HA-Host
Ha-Gx-Prefs
HA-Georegion
HA-Ipaddr
HA-Servedtime
X-Cache-CFC
X-Node-Id
HA-Urlpath
HA-Geolon
HA-Geolat
GMS-Ver
Magicmarker
Release
X-Block-Status
HA-Cloudapp
HA-Geocountry
HA-Geocity
X-Origin-TTL
X-Hash
X-Sorting-Hat-PodId
X-Shopify-Stage
X-ShopId
X-Sorting-Hat-ShopId
X-RateLimit-Remaining-Second
X-Wikidot-Static-Cache
X-RateLimit-Limit-Second
X-ShardId
Web-Mar-Node
X-GeoIP-City
Pagetype
X-Hl-Ver
X-Hnp-Log
X-Gen-Mode
X-Alternate-Cache-Key
Server-Host
X-Wikidot-Backend
X-Phone
X-Key
X-Policy
X-Eu-Site
Backend-Name
X-Platform
X-No-Session
X-Layer
X-External-Request-Id
AKAMAI
X-We-Are-Hiring
REQUESTUUID
X-Web-Node
X-VServer
X-Fastly-Cache
X-VCT
X-F5-Cache
SN
X-B3-TraceId
X-Endurance-Cache-Level
X-CACHE-AGE
X-Webstats-RespID
X-C
X-Location
X-Developers
X-Instance-Name
X-Debug-Log
Thinkindot-Control
X-Matched-Rule
X-Passed-To-PostProcessResponse
X-Debug-Cookies
X-Epic-Correlation-Id
X-Fetched-On
X-Reboot
X-GeoIP-Country-Code
X-Request-URI
X-HTML-Minification-Powered-By
X-Gannett-Site-Version
X-FW-Version
X-MI-In-Market
X-RCS-CacheZone
Uber-Trace-Id
X-Core-Value
X-Cache-URL
X-Backend-Url
X-Backend-TTL
X-Backend-State
X-NX-Host
Thinkindot-CacheControl-Type
X-Nginx-Cache-Key
X-MSEdge-Flight
X-Cache-Srv
X-Backend-Host
X-Cdn-Srv
X-Actual-URL
X-Core-Mission
X-Passed-To-BeforeDispatch
X-Cache-Expires
X-Clientip
X-Passed-To
X-Owner
X-GZip
X-MSEdge-Features
X-Passed-To-DLL
Request-Country
X-Sf
Kp-EeAlive
X-Varnish-Action
X-Variation
MI-API
MI-Cache
X-Server-IP
X-Tumblr-Pixel-3
Apple-News-Services-Request-Url
MI-Cache-Age
Is-Eu
CDCHOST
X-Thinkindot-L3
X-TT-LOGID
Countrycode
Esi-Enabled
Thinkindot-CacheControl
X-Swa-Ws
X-Var-Ttl
X-Up
Heartbleed
X-Stale
Odigeo-Trace-Id
Apple-News-Services-Parsed-Url
Apple-News-Services-Host
X-Returned-From-PostProcessResponse
X-Returned-From-DLL
Section-Io-Cache
X-Response-By
X-Returned-From-BeforeDispatch
X-Returned-From
Request-EU
X-Secret
Origin
Apple-News-Services-Handled
Platform
Adler-Geo
X-ElasticPress-Search
Proxy-Connection
X-Ua
X-Ezoic-Cdn
Resin-Trace
Decoy-Debug-Status
Decoy-Debug-TTL
X-Croise-Owner
Decoy-Debug-Key
Cache-Cookie-Set-From
Cache-Tags
X-Fstrz
X-Worker
Cache-Cookie-Set-Idcheck
X-Device-Os
Cache-Cookie-Set-Lfrom
Content-Disposition
X-Cdn-Origin
On-Server
X-Content-Age
X-ServiceProvider
X-Newrelic-Synthetics
X-V
RNT-Machine
True-Client-Country-4JS
X-Oracle-Dms-Ecid
Server-ID
RNT-Time
X-NWS-UUID-VERIFY
X-Servername
X-Cache-Host
X-Ckpd-Fst-Backend
Fastly-Backend-Name
X-Sn-Servicetimems
X-Nc
X-Trace-Id
X-Dc
Fastly-SWR
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
MIME-Version
X-Surge-Debug
HTTPS
X-Skip-Cache
Host-ID
X-Alicdn-Da-Ups-Status
Warning
Fastly-SIE
X-Csrf-Token
XServer
PageSpeed
X-Pf-Uncompressing
Cteonnt-Length
X-Req
X-Proto
X-TIME
Sid
X-Aed
Request-Time
RequestId
PFcat
X-Refresh
X-Atg-Version
Pramga
We-Hiring
Mail-Subject
X-Dynatrace-Js-Agent
X-Edge-IP
X-PHP-Backend
X-GEO
CF-IPCountry
X-Datadome
TSSecure
X-Time
X-Pjax-Url
X-Ms-Lease-State
X-Geo
X-Varnish-Ttl
X-Cdn-Forward
X-Planisys-CDN-Cache
X-Flog
X-Hello
X-Server-W
X-Planisys-CDN-Rules
X-Page-Type
X-Servedbyhost
X-ABtesting
X-Planisys-CDN-TTL
WP-Super-Cache
X-CLOUD-TRACE-CONTEXT
X-DC
CDN
X-Ratelimit-Limit
X-Oss-Storage-Class
X-COUNTRY
X-Oss-Server-Time
X-Oss-Object-Type
X-Oss-Hash-Crc64ecma
X-Varnish-Url
X-Oss-Request-Id
Cdn
Geoip-Latitude
GeoIp-Country-Code
Lfy
X-CSRF-Token
X-Auto-Login
Dnion-Transfer-Encoding
X-Cache-ASPX
Mime-Version
FSS-Proxy
X-DataStream-Origin-MEX-Latency
X-GoCache-CacheStatus
X-Unique-Id
FSS-Cache
X-DataStream-MidMile-RTT
X-Aicache-OS
X-Varnish-Beresp-TTL
A
X-Akamai-Request-ID2
X-Sentry-ID
Rt-Proxy-Cache
X-WA
MS-CV
X-GRACE
PageType
NnCoection
X-Origin-Expires
X-EC-Security-Audit
X-Via-NSCOPI
X-Origin-Date
NODE
X-MP-GENERATED-AT
X-Varnish-HitMiss
X-Cache-Control-Set-By
X-HCF
Node
Memcached
X-Cache-Id
X-Wa
X-Check-Cacheable
SD-X-WS
X-Thanos
X-Cache-Info
Hostname
X-Bip
X-Served-From
X-Use-Magma
X-APP
X-Be
GeoIP-Country-Code
GeoIP-Latitude
X-Proxy-Server
WWW-Authenticate
X-UPSTREAM-Address
X-Server-Group
X-Nananana
X-NODE
GeoIP-City
X-SRV
X-Ratelimit-Remaining
Geoip-City
X-Request-Start
Memory
X-Wix-Route-ID
UCS
X-Fastly-Cache-Hits
GW-Server
X-CACHE-KEY
PICS-Label
X-Cookie
X-PAGE-TYPE
X-Varnish-URL
Processtime
X-ServedByHost
X-From-Cache
X-GDPR
X-Gen-Id
X-Load-Cache
X-WR-MODIFICATION
DataCenter
X-RTag
Ms-Operation-Id
Cache-Hits
X-User
X-FORWARDED-FOR
X-Edge-Server
X-HS-Status
Cdn-Host
X-Gdpr
Cdn-Request-Time
X-Fastly-Backend-Reqs
Accept-Language
X-PJAX-URL
Pics-Label
X-Vcache
X-Goog-Meta-Goog-Reserved-File-Mtime
Cf-Ipcountry
COMMERCE-SERVER-SOFTWARE
X-Swift-Error
X-LI-Proto
X-Li-Pop
X-LI-UUID
X-Urbn-Context-Path
X-Li-Fabric
Locale
Dont-Set-Cookie
X-Cache-Ttl
X-B3-SpanId
X-Urbn-Site-Id
X-BBXSRF
X-Cache-Debug
X-Path-Route
Requestid
X-Env
X-Info
V-Cache
X-Cache-HT
Lb
X-RateLimit-Reset
X-Optimization
X-CDN-Pop
X-CDN-Pop-IP
Group
X-Dw-Trace-Id
Is-Session-Tracking
X-Fe
X-VG-WebCache
Get-Access-Time
Amp-Access-Control-Allow-Source-Origin
X-ID
NX-Cache
X-Qloud-Router
SS
Who
X-PF-Uncompressing
X-Content-Encoded-By
X-GZIP
URI
X-Bug-Bounty
Fastly-Soc-X-Request-Id
Serverid
X-NGINX-Cache
X-P-T
X-Akamai-SSL-Client-Sid
AGE-Hash
X-Cache-FS-Status
CDN-Cache
X-CacheKey
Xet-Cookie
CDN-Cache-Hit
X-Varnish-Info
X-Ver
CDN-Node
X-Litespeed-Cache-Control
X-SN
X-Flags
X-Meta-Tbi-Cache-Vertical
SID
X-Serial
X-BE
X-SB
X-Is-Crawler
X-ServerName
N-Cache
Https
X-Grace-Duration
X-Ibm-Trace
X-VC
X-Akamai-ERRuleID
X-Akamai-ERPolicy
X-Route-Name
Ws
X-Shard
X-RequestId
X-Providence-Cookie